Sansec Says Magento Zero-Day Is Backdooring Stores

Sansec said on September 5 that attackers are exploiting a new unauthenticated zero-day in Magento Open Source and Adobe Commerce, with attacks starting September 4 and at least one compromised store already running 2.4.6-p15 with the latest Adobe security updates applied. Sansec named the flaw StyleSmuggler and said it reproduces on current 2.4.x releases, including 2.4.9. The attack does not need a password or admin session. A malicious request can make the store execute code on its server, and successful intrusion can leave a persistent backdoor, so the compromise can survive the first break-in and not be solved by patching alone. Disrex Group also reported two compromised stores and one attempted attack, giving independent evidence outside Sansec. For shops running Magento or Adobe Commerce, especially headless and PWA storefronts that depend on GraphQL, this is live takeover territory before Adobe has published a fix. The open question is how far the exploitation has spread and which Adobe Commerce variants are affected, but current 2.4.x deployments should treat the exposure as active now.

Part of the PlainSec briefing for 2026-09-07

Every edition of this story: Sansec Says Magento Zero-Day Is Backdooring Stores

Sources